Data Storage Policy
Effective Date: 31 July 2026
1. Purpose
This Data Storage Policy defines the technical standards and practices for storing personal information at The Payments Club. It ensures that all personal information is stored securely, with appropriate encryption, access controls, and backup procedures, in compliance with POPIA and other applicable laws.
2. Storage Locations
- Primary Storage: All personal information is stored on secure servers hosted in South Africa or jurisdictions that meet POPIA's cross-border transfer conditions.
- Backup Storage: Encrypted backups are maintained in geographically separate locations to ensure business continuity.
- Third-Party Services: Where third-party processors are used, they are subject to data processing agreements that comply with POPIA.
3. Encryption Standards
- Data at Rest: All stored data is encrypted using industry-standard encryption (AES-256 or equivalent).
- Data in Transit: All data transmitted between systems is encrypted using TLS 1.2 or higher.
- Backup Encryption: Backups are encrypted using the same standards as primary storage.
- Password Hashing: User passwords are stored using bcrypt with a work factor of 12 or higher.
4. Access Controls
- Role-Based Access: Access to personal information is restricted based on role and necessity.
- Least Privilege: Users have only the minimum access required to perform their functions.
- Authentication: Multi-factor authentication is required for administrative access.
- Audit Logging: All access to personal information is logged for audit purposes.
- Access Reviews: User access is reviewed regularly.
5. Backup and Recovery
- Backup Frequency: Automated backups are performed daily.
- Recovery Point Objective (RPO): Maximum data loss of 24 hours.
- Recovery Time Objective (RTO): Maximum downtime of 4 hours.
- Backup Testing: Restore procedures are tested quarterly.
- Backup Storage: Backups are stored in encrypted form in a separate location.
6. Data Segregation
- Test/Production Separation: Test and development environments use anonymised data only.
- Multi-Tenant Separation: Data is logically segregated to ensure privacy between tenants.
- Data Classification: Data is classified and handled according to its sensitivity level.
7. Secure Disposal
- Electronic Data: Permanently deleted using secure deletion methods (overwriting or cryptographic erasure).
- Physical Media: Hard drives and other media are physically destroyed or degaussed.
- Documentation: Secure disposal is documented for audit purposes.
8. Monitoring and Security
- Security Monitoring: Continuous monitoring for unauthorized access attempts.
- Intrusion Detection: Systems in place to detect and alert on suspicious activity.
- Vulnerability Management: Regular vulnerability assessments and penetration testing.
- Incident Response: Documented procedures for responding to security incidents.
9. Responsibilities
- Information Officer: Overall accountability for data storage compliance.
- System Administrators: Technical implementation of storage and security controls.
- All Staff: Compliance with data storage policies and procedures.
10. Policy Review
This policy will be reviewed annually and on any material change to systems or storage practices. The latest version is always published on our website.
Last Updated: 31 July 2026